HTTP: MPG123 Streaming Audio Heap Overflow
This signature detects attempts to exploit a malicious server response to a streaming audio request from a mpg123 client; mpg123 versions 0.59r and 0.59s are vulnerable. Attackers can execute arbitrary commands on the client.
Extended Description
A problem in the handling of some types of remote files has been reported in mpg123. Because of this, it may be possible for a remote attacker to execute arbitrary code with the privileges of the mpg123 user.
Affected Products
Mandriva corporate_server
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Mpg123
Mandriva
7.5